vendor:
Dup Scout Enterprise
by:
Tulpa / tulpa[at]tulpa-security[dot]com
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: Dup Scout Enterprise
Affected Version From: Dup Scout Enterprise 9.0.28
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 x86 Enterprise SP1
Dup Scout Enterprise 9.0.28 Buffer Overflow Exploit
This exploit targets a buffer overflow vulnerability in Dup Scout Enterprise 9.0.28. It allows an attacker to execute arbitrary code and gain NT AUTHORITYSYSTEM privileges without authentication. The exploit has been tested on Windows 7 x86 Enterprise SP1. The payload size is 308 bytes.
Mitigation:
Update to a patched version of Dup Scout Enterprise.